
volatility3
Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Investigate malicious Windows logon by visualizing and analyzing Windows event log


Extract Windows credentials directly from VM memory snapshots and virtual disks

Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

Android Logs Events And Protobuf Parser

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Volatility plugin for extracts configuration data of known malware

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Digital forensic acquisition tool for Windows based incident response.

A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️

A python script developed to process Windows memory images based on triage type.

A Windows kernel dump C++ parser library with Python 3 bindings.

Automagically extract forensic timeline from volatile memory dump

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…